Events Calendar For Divi Security & Risk Analysis

wordpress.org/plugins/event-manager-for-divi

Revolutionize event pages with Events Calendar For Divi. Elevate design and engage visitors effortlessly.

60 active installs v5.0.2 PHP 7.4.3+ WP 4.5+ Updated Apr 8, 2025
dividivi-calendardivi-eventsdivi-events-calendarevents-calendar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Events Calendar For Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Events Calendar For Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12mo ago
Risk Assessment

The event-manager-for-divi plugin, version 5.0.2, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and performing a high percentage of output escaping. It also has no recorded vulnerabilities (CVEs) and no known critical or high-severity taint flows, which is a strong indicator of developer attention to secure coding. The absence of file operations and external HTTP requests further reduces potential attack vectors.

However, there are significant concerns. The plugin exposes one REST API route without any permission callbacks, creating a direct entry point into the application that is not protected by authentication or authorization checks. This unprotected entry point, coupled with the absence of nonce checks and capability checks across the board, presents a notable risk. While the code signals don't indicate dangerous functions or unsanitized paths in taint analysis, the lack of proper authentication on the REST API route is a critical oversight that could potentially be exploited if the route handles any user-supplied input or performs sensitive actions.

In conclusion, while the plugin benefits from solid database and output handling, the single unprotected REST API route is a significant weakness. The lack of any recorded vulnerabilities in its history is positive, but it does not negate the immediate risk posed by the identifiable unprotected entry point. Developers should prioritize addressing the missing permission callbacks for the REST API route to enhance the plugin's overall security.

Key Concerns

  • REST API route without permission callbacks
  • No nonce checks
  • No capability checks
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

Events Calendar For Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Events Calendar For Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
220 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

92% escaped240 total outputs
Attack Surface
1 unprotected

Events Calendar For Divi Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/wpt-events/v1/events/includes\classes\Event\Rest.php:24
WordPress Hooks 8
filtershow_first_trial_after_n_secevent-manager-for-divi.php:24
actionadmin_noticesincludes\classes\Loader.php:121
actionet_builder_readyincludes\classes\Loader.php:128
actiondivi_extensions_initincludes\classes\Loader.php:137
actionadmin_headincludes\classes\Loader.php:138
actionwp_enqueue_scriptsincludes\classes\Loader.php:142
actionpre_get_postsincludes\classes\Loader.php:145
actionrest_api_initincludes\classes\Loader.php:155
Maintenance & Trust

Events Calendar For Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 8, 2025
PHP min version7.4.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Events Calendar For Divi Developer Profile

wptools

15 plugins · 6K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Events Calendar For Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/event-manager-for-divi/assets/css/event-manager-for-divi.css/wp-content/plugins/event-manager-for-divi/assets/js/event-manager-for-divi.js
Script Paths
/wp-content/plugins/event-manager-for-divi/assets/js/event-manager-for-divi.js
Version Parameters
event-manager-for-divi/assets/css/event-manager-for-divi.css?ver=event-manager-for-divi/assets/js/event-manager-for-divi.js?ver=

HTML / DOM Fingerprints

CSS Classes
et_fb_wpt_event_content
REST Endpoints
/wp-json/wpt-events/v1/events/
FAQ

Frequently Asked Questions about Events Calendar For Divi